9.8

CVE-2023-3935

A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system.

Data is provided by the National Vulnerability Database (NVD)
WibuCodemeter Runtime Version < 7.60c
TrumpfOseon Version >= 1.0.0 <= 3.0.22
TrumpfProgrammingtube Version >= 1.0.1 <= 4.6.3
TrumpfTeczonebend Version >= 18.02.r8 <= 23.06.01
TrumpfTops Unfold Version05.03.00.00
TrumpfTopscalculation Version >= 14.00 <= 22.00.00
TrumpfTrumpflicenseexpert Version >= 1.5.2 <= 1.11.1
TrumpfTrutops Version >= 08.00 <= 12.01.00.00
TrumpfTrutops Cell Classic Version <= 09.09.02
TrumpfTrutops Cell Sw48 Version >= 01.00 <= 02.26.0
TrumpfTrutops Mark 3d Version >= 01.00 <= 06.01
TrumpfTrutopsboost Version >= 06.00.23.00 <= 16.0.22
TrumpfTrutopsfab Version >= 15.00.23.00 <= 22.8.25
TrumpfTrutopsfab Storage Smallstore Version >= 14.06.20 <= 20.04.20.00
TrumpfTrutopsprint Version >= 00.06.00 <= 01.00
TrumpfTrutopsweld Version >= 7.0.198.241 <= 9.0.28148.1
TrumpfTubedesign Version >= 08.00 <= 14.06.150
PhoenixcontactActivation Wizard SwPlatformmoryx Version <= 1.6
PhoenixcontactIol-conf Version <= 1.7.0
PhoenixcontactModule Type Package Designer Version1.2.0 Updatebeta
PhoenixcontactPlcnext Engineer Version <= 2023.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.445
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
info@cert.vde.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.